Bug 1081303 - (CVE-2018-6930) VUL-1: ImageMagick: CVE-2018-6930: ImageMagick: Stack-based buffer over-read in the ComputeResizeImage function
(CVE-2018-6930)
VUL-1: ImageMagick: CVE-2018-6930: ImageMagick: Stack-based buffer over-read ...
Status: RESOLVED WORKSFORME
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P4 - Low : Minor
: ---
Assigned To: Petr Gajdos
Security Team bot
https://smash.suse.de/issue/199921/
maint:planned:update CVSSv2:NVD:CVE-...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2018-02-16 08:53 UTC by Victor Pereira
Modified: 2018-04-18 11:09 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2018-02-16 08:53:55 UTC
rh#1544789

A stack-based buffer over-read in the ComputeResizeImage function in the
MagickCore/accelerate.c file of ImageMagick 7.0.7-22 allows a remote attacker to
cause a denial of service (application crash) via a maliciously crafted pict
file.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1544789
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-6930
http://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-6930.html
http://www.cvedetails.com/cve/CVE-2018-6930/
https://github.com/ImageMagick/ImageMagick/issues/967
Comment 1 Petr Gajdos 2018-04-18 11:09:23 UTC
I do not see the code anywhere in ImageMagick 6 versions we maintain, considering unaffected.

Even ImageMagick-7.0.7-25 contained in SUSE:SLE-15:GA has the fix in already.